Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.

It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.

“The PoC requires

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

US holds off blacklisting DeepSeek, more than 100 firms deemed security risks

US holds off blacklisting DeepSeek, more than 100 firms deemed security risks Source: Hacker News

Netflix employee fired for sharing personal details in retreat trust exercise

Netflix employee fired for sharing personal details in retreat trust exercise Source: Hacker News

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six